Splunk Search

How to configure Splunk to index PSV files and extract field names from the header/first row?

dhavamanis
Builder

We are trying to index a psv file into Splunk with sourcetype as "psv", but its not extracting fields from the PSV's first row. Can you please provide the config to add fields as psv header/first row values.

0 Karma
1 Solution

dhavamanis
Builder

Thanks, configured props.conf at forwarder end and its working fine.

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!